GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,847
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,579
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
180 advisories
Filter by severity
HTTPX2: Quadratic SSE line buffering can cause CPU denial of service
Moderate
CVE-2026-84378
was published
for
httpx2
(pip)
Sep 8, 2026
Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsing
Moderate
CVE-2026-75596
was published
for
io.netty:netty-handler
(Maven)
Sep 8, 2026
commonmark versions from 1.5.0 before 2.10.0 contain a denial of service vulnerability in the...
High
Unreviewed
CVE-2026-86428
was published
Sep 7, 2026
league/commonmark versions before 2.9.1 contain multiple denial of service vulnerabilities in...
High
Unreviewed
CVE-2026-86430
was published
Sep 7, 2026
commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the...
High
Unreviewed
CVE-2026-86433
was published
Sep 7, 2026
league/commonmark versions >= 2.0.0 and < 2.8.4 (patched in 2.9.0) contain a denial of service...
High
Unreviewed
CVE-2026-86434
was published
Sep 7, 2026
commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the...
High
Unreviewed
CVE-2026-86435
was published
Sep 7, 2026
The league/commonmark (thephpleague/commonmark) library in versions >= 1.5.0 and < 2.9.1 contains...
High
Unreviewed
CVE-2026-86429
was published
Sep 7, 2026
MOOS-IvP versions through 24.8.1 contain a quadratic processing vulnerability in uFldNodeComms...
High
Unreviewed
CVE-2026-85446
was published
Sep 4, 2026
stream-json: pick/ignore/filter/replace filters are O(depth²) on nested input — small crafted JSON blocks the event loop for seconds→minutes (DoS)
Moderate
CVE-2026-71429
was published
for
stream-json
(npm)
Sep 3, 2026
pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespace
Moderate
CVE-2026-82398
was published
for
pypdf
(pip)
Sep 2, 2026
NLTK: Quadratic-time DoS in PorterStemmer via long runs of 'y'
Moderate
CVE-2026-81722
was published
for
nltk
(pip)
Sep 2, 2026
NLTK: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()`
Moderate
CVE-2026-81723
was published
for
nltk
(pip)
Sep 2, 2026
NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars
Moderate
CVE-2026-12876
was published
for
nltk
(pip)
Sep 2, 2026
sqlparse: Reindentation of tuple lists causes near-cap quadratic CPU consumption
Moderate
CVE-2026-84305
was published
for
sqlparse
(pip)
Sep 1, 2026
league/commonmark: Denial of service via distinctly-named attributes in the Attributes extension
High
GHSA-8rr7-cvq3-gmfh
was published
for
league/commonmark
(Composer)
Sep 1, 2026
league/commonmark: Denial of service in the SmartPunct and Attributes extensions
High
GHSA-jjv6-8j6v-6j52
was published
for
league/commonmark
(Composer)
Sep 1, 2026
league/commonmark: Denial of service via crafted code fences, reference links, and emphasis delimiters
High
GHSA-j8pm-gj4c-rq4x
was published
for
league/commonmark
(Composer)
Sep 1, 2026
A flaw was found in openshift/oauth-server. The OAuth login and error page endpoints pass the...
High
Unreviewed
CVE-2026-49329
was published
Sep 1, 2026
decode-uri-component: Denial of service via exponential decoding of malformed percent-encoded input
Moderate
CVE-2026-45822
was published
for
decode-uri-component
(npm)
Aug 31, 2026
Duplicate Advisory: Quadratic-time DoS in PorterStemmer via long runs of 'y'
High
GHSA-8x48-8g7j-rqxp
was published
for
nltk
(pip)
Aug 27, 2026
•
withdrawn
Inefficient Algorithmic Complexity vulnerability in Apache APISIX.
A single small request can...
High
Unreviewed
CVE-2026-75005
was published
Aug 27, 2026
An algorithmic complexity flaw exists in libsoup's HTTP Range header processing that persists...
Moderate
Unreviewed
CVE-2026-77680
was published
Aug 25, 2026
icalendar has Algorithmic Complexity in Equality
High
CVE-2026-55099
was published
for
icalendar
(pip)
Aug 25, 2026
In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka...
Moderate
Unreviewed
CVE-2026-76401
was published
Aug 20, 2026
ProTip!
Advisories are also available from the
GraphQL API